A new report finds that government legal agencies are embracing AI to improve efficiency while navigating critical data privacy, security, and confidentiality risks.
Limited staffing is motivating government legal organizations to adopt AI tools to automate time-consuming tasks and work more efficiently. Not surprisingly, attorneys at private legal organizations — either in law firms or corporate legal departments — have higher expectations of AI work-reduction gains, while government attorneys have the greater need for those gains.
Indeed, most government legal agencies already use case management and document management technology, but only one-third use legal industry-specific generative AI (GenAI) tools or plan to soon (6) — and only 7% use any form of agentic AI (18).
The Thomson Reuters Institute’s recent 2026 Government Legal Department Report — which surveyed hundreds of attorneys in court-facing agencies at the federal, state, and municipal level — shows a clear acceleration of AI adoption among government legal departments, as well as increasing optimism around its potential. In fact, the report shows that optimism about AI among government lawyers has increased since 2024, although roughly the same percentage is still pessimistic.
However, there are significant concerns regarding the lack of clear guidelines around AI use and training. According to the report above, almost 80% of respondents say they are worried about exposure of confidential data (20) and 73% say the same about AI’s accuracy or errors. And one-third of respondents say they have concerns about how data is retained and where it resides (Figure 6, page 20).
Challenges facing government legal agencies
More worrisome for some government lawyers is that to realize AI’s efficiency gains, they may have to rely on cost-conscious third-party solutions. However, those can also require broader permissions for agency and vendor staff, increasing the risk of credential-based breaches. The same tools that help understaffed legal organizations work more efficiently can also increase the number of people, systems, and credentials they need to protect.
In a recent report about government adoption of AI and establishing guardrails, government AI builder Acquia note that: “Federal agencies are deploying AI at an accelerating pace, yet the absence of a unified, government-wide framework has left many without the skills, controls, or governance structures needed to manage the associated risks.”
Indeed, the Privacy Act of 1974 requires government employees to protect personally identifiable information (PII), including health and other information. Even as the regulatory environment is now urging innovation, attorneys still have both the ethical and practical motivation to scrutinize any new technology that affords more access to sensitive information than before. And court system electronic breaches that risk exposure of PII — including the information of defendants, plaintiffs, victims, and other parties — are increasing in frequency and scope.
The growing risk of shadow AI
Another concerning development is the use of shadow AI by government employees. Shadow AI refers to the use of AI tools by employees outside the agency’s approved IT systems. In a recent survey including government professionals, 27% said they had used outside AI tools in their work. Paradoxically, this may be because lawyers are frustrated with the slow pace of AI implementation within their agencies.
When government lawyers use non-authorized or public AI tools, however, the organization’s protection of PII is threatened in several ways, either by government employees unintentionally disclosing private information they think will be guarded or by outright breaches into the public AI tools that were used.
Building the right guardrails
Not surprisingly, survey respondents want clearer guidelines for AI use and support guardrails that prevent inadvertent data leakage.
Government agencies can discourage unauthorized AI use by implementing effective internal AI platforms. Agencies should also strengthen cybersecurity measures and use AI-assisted access and permission systems to help protect sensitive information. But they need a broader security plan that accounts for the different risk profiles of the AI systems they adopt.
Government agencies typically adopt AI in one of three ways: i) buying AI through offsite software-as-a-service (SaaS) with enhanced security; ii) building with AI by working with a third-party vendor to customize existing tools and security measures; or iii) owning AI by building, training, deploying, and maintaining the platform internally.
Costs increase across these three approaches. Government legal agencies typically have smaller AI budgets than private firms, which can limit them to the first two options. Because those options rely more heavily on external platforms or vendors, agencies may face greater risks of exposing personally identifiable information (PII).
Conclusion
Legal agencies have a unique set of heightened requirements regarding PII protection, but they have strained budgetary resources to do so. These same circumstances are pushing government legal agencies increasingly to seek AI automation of rote, repetitive, or more complex tasks. While government attorneys have shifted to more hopeful than trepidatious attitudes towards AI uptake in the last two years, there remain compelling reasons for concern.
Preparing skillfully for new risks while implementing AI tools to realize efficiency gains and prevent unauthorized AI use is a balancing act. As adoption accelerates, agencies will need a collaborative approach that manages risk, builds staff confidence, and meets today’s operational needs. That means attorneys and support staff need practical guidance on what tools can be used, how they’ll be trained on it, what information can be entered, and what safeguards should apply.
You can access the full 2026 Government Legal Department Report, from the Thomson Reuters Institute, here













Leave a Reply